Files
hayabusa/rules/timeline-rules/Logons/4634-Logoff.yml
T
Tanaka Zakku bad4429ad0 Rule tuning
2021-11-18 10:31:28 +09:00

19 lines
429 B
YAML

title: Logoff
description: Prints logon information
author: Zach Mathis
level: informational
detection:
selection:
Channel: Security
EventID: 4634
filter:
TargetUserName|endswith: "$"
condition: selection and not filter
falsepositives:
- normal system usage
output: 'Username: %TargetUserName% : LogonID: %TargetLogonId%'
creation_date: 2021/11/17
updated_date: 2021/11/17